soc2
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill consists entirely of markdown-based instructions and reference materials for SOC 2 compliance advice.
- [INDIRECT_PROMPT_INJECTION]: The skill defines workflows for analyzing external data such as vendor SOC 2 reports and security questionnaires. This creates an attack surface for indirect prompt injection if a third-party document contains adversarial instructions. However, the skill lacks dangerous capabilities—such as file system writes, network operations, or shell execution—that would allow for an exploit to cause harm.
- [SAFE]: The skill does not include any scripts, third-party dependencies, or remote code downloads. It relies entirely on the model's internal reasoning and the provided reference files.
Audit Metadata